MEDIUM · 6.3

CVE-2023-20016

A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to ...

Vulnerability Description

A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive information stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method used for the backup function. An attacker could exploit this vulnerability by leveraging a static key used for the backup configuration feature. A successful exploit could allow the attacker to decrypt sensitive information that is stored in full state and configuration backup files, such as local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and other credentials.

CVSS Score

6.3

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CiscoUcs Central Software< 4.2\(3c\)
CiscoUcs 6536 Firmware-
CiscoUcs 6536-
CiscoUcs 64108 Firmware-
CiscoUcs 64108-
CiscoUcs 6454 Firmware-
CiscoUcs 6454-
CiscoUcs 6200 Firmware-
CiscoUcs 6200-
CiscoUcs 6248Up Firmware-
CiscoUcs 6248Up-
CiscoUcs 6296Up Firmware-
CiscoUcs 6296Up-
CiscoUcs 6300 Firmware-
CiscoUcs 6300-
CiscoUcs 6324 Firmware-
CiscoUcs 6324-
CiscoUcs 6332 Firmware-
CiscoUcs 6332-
CiscoUcs 6332-16Up Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-20016?

CVE-2023-20016 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to ...

How severe is CVE-2023-20016?

CVE-2023-20016 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-20016?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ucs Central Software, Cisco Ucs 6536 Firmware, Cisco Ucs 6536, Cisco Ucs 64108 Firmware, Cisco Ucs 64108.